← back
CVE-2020-23972observed exploitation

CVE-2020-23972

72Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 31%
from disclosure to weapon96 days
Published on NVDAug 27
1st PoC+96d
VulnCheck+228d
exploitation probability
31%top 2% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.